DocumentCode
398064
Title
Integrating your information security vulnerability management capabilities through industry standards (CVE&OVAL)
Author
Martin, Robert A.
Author_Institution
Software Eng. Sect., MITRE Corp., Bedford, MA, USA
Volume
2
fYear
2003
fDate
5-8 Oct. 2003
Firstpage
1528
Abstract
There are important changes to the cyber-security industry, being fostered by the Common Vulnerability Exposures (CVE®) and Open Vulnerability Assessment Language (OVAL™) Initiatives, a pair of international, community-based effort amongst industry, government, and academia. These changes will transform the way your enterprise deals with vulnerabilities in the commercial and open source components of your enterprise infrastructure and mission systems. With approximately 150 organizations working to support the CVE standard in more than 250 cyber-security products and services, CVE is quickly becoming an organizing mechanism that can make enterprise management of information security vulnerabilities less of a labor intensive art and more of an engineered practice. The OVAL effort builds upon CVE to create a means for making vulnerability alerts more applicable to individual enterprises. OVAL is aimed to provide the means for standardized vulnerability assessment and result in consistent and reproducible information assurance metrics for systems.
Keywords
information management; security of data; standards; CVE standards; Common Vulnerability Exposures; OVAL standards; Open Vulnerability Assessment Language; commercial components; community based effort; cyber-security industry; enterprise management; individual enterprises; industry standards; information assurance metrics; information security; labor intensive art; management capabilities; mission systems; open source components; vulnerability; Computer errors; Computer hacking; Computer industry; Computer security; Information management; Information security; Intrusion detection; Open source software; Protection; Software tools;
fLanguage
English
Publisher
ieee
Conference_Titel
Systems, Man and Cybernetics, 2003. IEEE International Conference on
ISSN
1062-922X
Print_ISBN
0-7803-7952-7
Type
conf
DOI
10.1109/ICSMC.2003.1244628
Filename
1244628
Link To Document